Apache Tomcat Remote Code Execution Vulnerability
Release Date:
12 Mar 2025
395
Views
RISK: Medium Risk
TYPE: Servers - Web Servers

A vulnerability has been identified in Apache Tomcat. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.
Impact
- Remote Code Execution
System / Technologies affected
- Apache Tomcat version 11.0.0-M1 to 11.0.2
- Apache Tomcat version 10.1.0-M1 to 10.1.34
- Apache Tomcat version 9.0.0.M1 to 9.0.98
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.3
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.35
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.99
Vulnerability Identifier
Source
Related Link
Related Tags
Share with